Privacy policy
Last updated 19 August 2026. This covers the Fortis web vault, API, and browser extension.
What Fortis stores
Fortis is a zero-knowledge password manager. Login names, usernames, domains, descriptions, and passwords are encrypted on your device with a key derived from your master password. The server stores only ciphertext, an email address, a Google account id if you use Sign in with Google, a password-derived login hash, an encrypted TOTP secret, and hashed session tokens.
Sign in with Google
If you choose Google sign-in, Google shares your verified email and account id so Fortis can create or find your vault account. Fortis does not receive your Google password. Google Authenticator (TOTP) is required on every sign-in. The master password is still required to decrypt the vault and is never sent to Fortis or Google.
Browser extension
The extension reads login forms on websites you visit so it can offer to save or fill a matching Fortis entry. It does not send page contents to the server. Autofill happens only after you choose an entry. Session tokens and the vault unlock key live in extension storage for up to 30 days on this device (or until you lock or sign out).
What we do not do
We do not sell personal data, show ads, or recover a forgotten master password. We do not use SMS. Demo TOTP helpers are disabled on production deployments.
Contact
Questions: rod@rocostagames.com.